I suggest you ...

IPS: Per-Rule IPS Exceptions

Extended the exceptions functionality to allow for specific rules as part of an exception.

This will allow for much more granular IPS exceptions in being able to specify a rule be disable/excepted only for a certain traffic flow, like for rule 2122 from Internet to Webserver, without disabling the rule globally or by exempting the resource from IPS fully.

It would be great if that was implemented. At the moment you have to disable a complete rule instead of just eliminating false positives apearing inside your own network. Also as Elmar stated the exceptions are a bit useless without the possibility to combine source and destination via AND.

I agree, a v6 type configuration would be better that what's there now, but it needs to be flexible for new rules and edits to existing rules with the ability to revert an edited rule back to it's factory syntax.
There should also be a way to fetch rules files from a central location. I'm not going to pretend to know the details of that methodology, but it seems doable.

I'm outta votes, but we do need a way to add our own rules, as we could in Version 6. I think the current method for managing the automatic ruleset is OK,but we need the ability to add custom rules again.